CVE-2006-5855: Buffer Overflow
Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) the language field at logon that begins with a 0x18 byte, (2) two unspecified parameters to the SmExecuteWdsfSession function, and (3) the contact field in an open registration message.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5855?
CVE-2006-5855 has a severity rating that indicates it can lead to denial of service and potential remote code execution.
How do I fix CVE-2006-5855?
To fix CVE-2006-5855, upgrade IBM Tivoli Storage Manager to version 5.2.9 or 5.3.4 or higher.
What products are affected by CVE-2006-5855?
CVE-2006-5855 affects IBM Tivoli Storage Manager versions 5.2.7 through 5.2.8 and 5.3.0 through 5.3.3.
Can CVE-2006-5855 be exploited remotely?
Yes, CVE-2006-5855 can be exploited remotely by attackers sending specially crafted input to the vulnerable software.
What types of attacks does CVE-2006-5855 allow?
CVE-2006-5855 allows attackers to cause a denial of service crash and potentially execute arbitrary code on affected systems.